Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-74251CriticalCVSS 9.3CVE published 16 August 2026

Phoca Cart (com_phocacart) 3.x - Unauthenticated SQL Injection in the product filter, no fixed release

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Phoca fixed this on 16 August 2026 in 5.2.4 (Joomla 5 line) and 6.1.7 (Joomla 6 line). The Joomla 3 line was NOT patched: 3.5.8 is the newest 3.x release and it still contains the identical vulnerable code, so every 3.x version is affected with no fixed release available. There is no in-branch remedy. Migrate the site to a supported Joomla version and install the patched Phoca Cart, or remove the extension. The Joomla CNA published CVE-2026-74251 for this flaw on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89). The published affected range starts at 5.0.0, so it does not formally cover the 3.x branch, but we extracted 3.5.8 and confirmed the identical unpatched code, which is why this rule flags it.

Is my site affected?

CVE-2026-74251 is checked by 4 rules. Find the extension and release line your site runs:

ExtensionAffected versionsFixed inWhat to do
Phoca Cartfrom 3.0.0 up to but not including 4.0.04.0.0Update Phoca Cart to 4.0.0 for this flaw, or to 6.1.9 or later, which no rule we check matches.
Phoca Cartfrom 4.0.0 up to but not including 4.0.134.0.13Update Phoca Cart to 4.0.13 for this flaw, or to 6.1.9 or later, which no rule we check matches.
Phoca Cartfrom 5.0.0 up to but not including 5.2.45.2.4Update Phoca Cart to 5.2.4 for this flaw, or to 6.1.9 or later, which no rule we check matches.
Phoca Cartfrom 6.0.0 up to but not including 6.1.76.1.7Update Phoca Cart to 6.1.7 for this flaw, or to 6.1.9 or later, which no rule we check matches.

How CVE-2026-74251 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

9.3 Critical

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:H Availability
High. The site can be taken down

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

Timeline

  1. 16 August 2026CVE-2026-74251 record published by its CNA
  2. 16 August 2026We published: Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Rule details

Phoca Cart - Phoca Cart (com_phocacart) below 4.0.13 - Unauthenticated SQL Injection in the product filter

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Phoca fixed this on 16 August 2026 across three branches: 6.1.7 at 10:23 UTC, 5.2.4 sixteen minutes later, and 4.0.13 for the Joomla 4 line the same evening at 20:39 UTC. Update to 4.0.13 or later on the 4.x branch. The fix is in admin/libraries/phocacart/search/search.php and routes every filter value through $db->quote(); we confirmed it by extracting and diffing the shipped com_phocacart_v4.0.12.zip and com_phocacart_v4.0.13.zip packages rather than comparing git tags, which do not correspond to the released code on this project. The 4.x file has four injection points where the 5.x and 6.x files have six, because the 4.x line predates the multilingual code path. The Joomla CNA published CVE-2026-74251 on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89). The published affected range starts at 5.0.0 and does not formally cover the 4.x branch, but the identical vulnerable code is present in 4.0.12 and earlier, which is why this rule flags it.

Affected versions: ≥ 4.0.0 and < 4.0.13

Full advisory: our disclosure post

Phoca Cart - Phoca Cart (com_phocacart) below 5.2.4 - Unauthenticated SQL Injection in the product filter

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Update to Phoca Cart 5.2.4 or later on the Joomla 5 line. Note that Joomla 5 sites running a Phoca Cart 6.x version will NOT be offered this fix by the Joomla updater, because the update feed maps Joomla 5 to the 5.x release and 5.2.4 sorts lower than the installed 6.x version, so the update screen shows nothing: those sites need the 6.1.7 package installed manually. The Joomla CNA published CVE-2026-74251 for this flaw on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89).

Affected versions: ≥ 5.0.0 and < 5.2.4

Full advisory: our disclosure post

Phoca Cart - Phoca Cart (com_phocacart) below 6.1.7 - Unauthenticated SQL Injection in the product filter

Phoca Cart builds the product filter query by concatenating the a (attribute) and s (specification) request parameters straight into the WHERE clause inside hand-written quotes, instead of passing them through the database quoting. The front-end product listing model reads both parameters from the request using the Joomla array filter, which does not sanitise the values inside the array, so any anonymous visitor can reach the injection on a public product or category listing page with no account and no token. Update to Phoca Cart 6.1.7 or later. If this site runs Joomla 5 rather than Joomla 6, the Joomla updater will NOT offer 6.1.7: the update feed maps Joomla 5 to the 5.x release and 5.2.4 sorts lower than the installed 6.x version, so the update screen reports nothing to update. Download the 6.1.7 package from GitHub or phoca.cz and install it through Extensions, Install, Upload Package File. The Joomla CNA published CVE-2026-74251 for this flaw on 16 August 2026, scoring it CVSS 4.0 9.3 Critical (CWE-89). The record states the affected range as 5.0.0-6.1.16; there is no Phoca Cart 6.1.16, the highest release on the 6.x line is 6.1.7 and that is the build containing the fix, so read the upper bound as 6.1.6.

Affected versions: ≥ 6.0.0 and < 6.1.7

Full advisory: our disclosure post

Our disclosure post

Other vulnerabilities in Phoca Cart

Updating for CVE-2026-74251 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

Phoca Cart

Latest safe version: 6.1.9

References

CVE-2026-74251 questions

Which versions are affected by CVE-2026-74251?
CVE-2026-74251 is covered by 4 rules: Phoca Cart from 3.0.0 up to but not including 4.0.0; Phoca Cart from 4.0.0 up to but not including 4.0.13; Phoca Cart from 5.0.0 up to but not including 5.2.4; Phoca Cart from 6.0.0 up to but not including 6.1.7.
How do I fix CVE-2026-74251?
It depends on the extension and release line your site runs. For Phoca Cart from 3.0.0 up to but not including 4.0.0: update Phoca Cart to 4.0.0 for this flaw, or to 6.1.9 or later, which no rule we check matches. For Phoca Cart from 4.0.0 up to but not including 4.0.13: update Phoca Cart to 4.0.13 for this flaw, or to 6.1.9 or later, which no rule we check matches. For Phoca Cart from 5.0.0 up to but not including 5.2.4: update Phoca Cart to 5.2.4 for this flaw, or to 6.1.9 or later, which no rule we check matches. For Phoca Cart from 6.0.0 up to but not including 6.1.7: update Phoca Cart to 6.1.7 for this flaw, or to 6.1.9 or later, which no rule we check matches.
How severe is CVE-2026-74251?
Joomla CNA scores it 9.3 (Critical) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.